Identity Provider Integration, Directory Synchronization, and Single Sign-On
Integrates with major external identity providers (such as Google Workspace, Okta, and Microsoft Entra ID) to authenticate users via multi-factor authentication, PKCE, and OAuth scopes; enables automatic provisioning and synchronization of users, groups, and nested directory attributes alongside manual administration, and supports custom session lifetimes, role-based access controls, and browser-based sign-in using unique account slugs.
02
Browser-Based Authentication and Account Slug Configuration
Provides a secure sign-in experience using the default system browser with OAuth redirects, featuring persistent sign-in states, custom account sign-in URLs (slugs), and administrative controls to pre-configure account slugs to prevent unauthorized end-user modification.
03
Multi-Method Direct Authentication
Supports passwordless authentication via email using short-lived OTPs or secure sign-in links, as well as traditional username and password authentication with configurable session lifetimes, requiring manual user and group administration when utilizing these native methods.
04
Service Account Lifecycle and Access Management
Enables the creation, management, and authentication of non-human service accounts using long-lived client tokens with configurable expiration dates, supporting headless machine-to-machine or IoT connectivity directly through the API, manual access control with tiered limits, and instant token revocation.
05
Secure Token Storage and Session Lifetime Management
Stores and encrypts authentication tokens using platform-native secure storage systems (such as macOS/iOS Keychain or desktop keyrings) while enabling custom session lifetimes, token expirations, instant active session revocation, and security measures like random state/nonce validation and cryptographic WebSocket headers.
Your plan caps how many capabilities are shown — upgrade to see the full list